View Single Post
  #1  
Old 13th November 2005, 12:05
Ovidiu Ovidiu is offline
Senior Member
 
Join Date: Sep 2005
Posts: 1,265
Thanks: 80
Thanked 24 Times in 20 Posts
Default question regarding configuration of logcheck

hi guys,

anyone using logcheck?
If yes did you change the ignore files? I am using it in server mode or server level but it still keeps showing me some stupid logs which I want to get rid of: one example would be that it does not filter lines like this:
Quote:
Nov 12 18:04:20 h5810 proftpd: (pam_unix) session opened for user web18_admin by
(uid=0)
also in /etc/logcheck/ignore.d.server/proftpd there is this line:
Quote:
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ proftpd: \(pam_unix\) session (opened|closed) for user [\._[:alnum:]-]+( by \(uid=[0-9]+\))$
a line that I did not insert but was there from the start.

logcheck is set up to be in server mode
Reply With Quote
Sponsored Links